Masuta is a Mirai-derived botnet malware family targeting Linux-based IoT devices and network equipment. It recruits compromised devices into remotely controlled botnets used for distributed denial-of-service attacks. Masuta is associated with Kenneth Crurrin Schuchman, also known as Nexus Zeta, and co-conspirators who created and monetized multiple botnets, including Satori, Okiru, and Fbot. Leaked Masuta source code helped establish its connection to Nexus Zeta.
PureMasuta is a related variant that expands the botnet by exploiting a D-Link Home Network Administration Protocol implementation vulnerability. Crafted SOAP requests combine authentication bypass with command injection to achieve arbitrary code execution on vulnerable devices. Masuta and PureMasuta shared command-and-control infrastructure, supporting their association with the same operators. The family belongs to the ecosystem of Mirai derivatives that emerged after Mirai's source code was publicly released in 2016.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Two related Mirai variants called Masuta and PureMasuta have links to a hacker identified as Nexus Zeta.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a Mirai variant resulting from reuse of its leaked source code. No variant-specific capabilities or campaign details are provided.
Masuta is cited as a Mirai variant resulting from the leaked Mirai source code.
Named in the legal-background update as one of the botnets created through device infections by Kenneth Schuchman and his co-conspirators for financial gain. No technical details about Masuta are provided.
A Mirai-derived IoT botnet malware variant linked to Nexus Zeta. It is used to compromise internet-connected devices and expand a botnet, and shares infrastructure with PureMasuta.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.